Security policy
Last reviewed August 26, 2026Actuneuriat welcomes good-faith vulnerability reports that protect readers and the publication.
How to report
Send a concise description, affected URL, reproduction steps and potential impact. Do not include unnecessary personal data or publicly disclose an unresolved issue.
Good-faith testing
Limit testing to your own accounts and data, avoid service disruption, do not use social engineering, and stop immediately if you encounter personal data, credentials or a system outside the intended public surface.
Response
Actuneuriat will acknowledge a useful report when operationally possible, investigate proportionately and coordinate a reasonable disclosure timeline. This policy is not a bug-bounty promise or authorization to violate law or third-party terms.
Current controls
The publication minimizes active application surfaces, does not expose reader accounts or public write APIs at launch, validates release builds and applies browser security headers at the delivery layer.